Introduction
The Foreign Corrupt Practices Act (FCPA), enacted by Congress in 1977 and significantly strengthened by amendments in 1988 and 1998, remains one of the most consequential and aggressively enforced pieces of anti-corruption legislation in the world. The statute makes it unlawful for US companies and persons, as well as foreign companies whose securities are listed on US exchanges and their agents, to bribe foreign government officials in order to obtain or retain business. The FCPA also contains robust accounting provisions requiring issuers to maintain accurate books and records and implement adequate internal controls.
For American businesses operating in the global marketplace, FCPA exposure is not a theoretical concern. The Department of Justice (DOJ) and the Securities and Exchange Commission (SEC) have collected billions of dollars in FCPA-related fines and penalties over the past two decades, and enforcement actions have reached into nearly every major sector of the economy. In fiscal years 2020 through 2024, the government secured more than $10 billion in corporate FCPA resolutions, with individual cases routinely resulting in fines exceeding $100 million. Beyond monetary penalties, FCPA enforcement can bring deferred prosecution agreements imposing years of costly compliance monitoring, reputational damage that ripples across global operations, and, in serious cases, criminal prosecution of individual executives.
Not all businesses carry equal FCPA risk. A company’s exposure depends on a number of interacting factors: the extent of its international operations, the industries in which it operates, the degree to which it relies on foreign government contracts or regulatory approvals, the markets in which it does business, and the adequacy of its internal compliance infrastructure. This article examines the industries and business models that US prosecutors and regulators have historically viewed as highest-risk, explains the structural factors that drive that risk, and outlines what businesses in these sectors should consider as a matter of good governance and legal prudence.
The Core Risk Factors: Why Some Businesses Are More Exposed Than Others
Before turning to specific industries, it is useful to identify the structural features that create FCPA risk. The most important is the degree to which a business depends on decisions made by foreign government officials. In many countries, the line between private enterprise and the state is far thinner than American executives expect. State-owned enterprises (SOEs) are pervasive in sectors such as telecommunications, energy, banking, and defense procurement in Asia, Latin America, the Middle East, and Africa. An SOE employee can qualify as a “foreign official” for FCPA purposes, meaning that payments or other benefits provided to that individual in connection with obtaining or retaining business may trigger FCPA liability.
A second major driver of FCPA risk is operating in markets where corruption is endemic or where bribery is treated as a customary cost of doing business. Transparency International’s Corruption Perceptions Index consistently identifies countries in sub-Saharan Africa, Southeast Asia, Central Asia, the Middle East, and parts of Latin America as presenting elevated corruption risk. American companies entering or operating in these markets must build compliance safeguards that are proportionate to the local risk environment.
A third driver is the use of third-party intermediaries: agents, distributors, consultants, joint venture partners, or customs brokers who interact with foreign government officials on a company’s behalf. A disproportionate share of FCPA enforcement actions involve payments made not by company employees directly, but through local intermediaries who are not subject to the same oversight and whose conduct is nonetheless imputed to the US company. The FCPA does not require actual knowledge of an intermediary’s corrupt acts; a company may be liable if it was willfully blind to red flags suggesting that its agent was engaging in bribery.
Against this backdrop, the following industries stand out as historically presenting the greatest FCPA risk for US businesses.
The Oil, Gas, and Energy Sector
No industry has generated more FCPA enforcement activity than oil, gas, and energy. The combination of vast sums at stake, pervasive state ownership of natural resources, and operations concentrated in high-corruption jurisdictions makes this sector a perennial priority for DOJ and SEC enforcement. Some of the largest FCPA settlements in history have involved energy companies: Petrobras-related conduct, the Unaoil scandal implicating companies across the energy services supply chain, and enforcement actions against Halliburton, KBR, and Technip have defined the scope and reach of FCPA enforcement in this space.
The structural features driving energy sector risk are straightforward. Hydrocarbon deposits and power infrastructure in much of the world are owned or controlled by governments. Licenses, permits, concession agreements, and production-sharing contracts must be obtained from or negotiated with state authorities. In countries with weak rule of law, local officials routinely demand payments as a condition of doing business. Energy companies often rely heavily on local agents and joint venture partners who may engage in conduct that benefits the US parent company without its explicit knowledge. And the scale of contracts in the sector—often running to hundreds of millions or billions of dollars—creates strong economic incentives to make improper payments that, in percentage terms, may seem modest relative to the business at stake.
The risk extends throughout the energy supply chain, from oilfield services companies and drilling contractors to pipeline operators, LNG terminal developers, and renewable energy project developers who must navigate complex government permitting and grid interconnection processes in emerging markets.
Defense, Aerospace, and Government Contracting
Defense and aerospace companies occupy a uniquely exposed position under the FCPA because their primary customers, by definition, are governments. A contract to supply fighter aircraft, naval vessels, radar systems, or military communications equipment must be won through a procurement process controlled by foreign defense ministries and government officials. The value of individual contracts can be extraordinary, and competition among US and non-US defense contractors for a limited number of large procurements creates powerful financial pressures.
Enforcement history in this sector is extensive. Lockheed Martin’s predecessor companies were at the center of the original bribery scandals that prompted Congress to enact the FCPA in 1977. More recent enforcement actions have targeted companies across the defense and aerospace supply chain for improper payments to procurement officials, defense ministers’ staff, and intermediaries with connections to government decision-makers. The use of commission-based local agents—standard commercial practice in many markets—has been a recurring source of FCPA exposure when agents use a portion of their commissions to pay government officials.
Government IT contractors, intelligence services companies, and providers of border control or surveillance technology face similar structural risks, particularly as foreign governments increasingly purchase sophisticated technology systems from US vendors through opaque procurement processes in jurisdictions with limited anti-corruption enforcement.
Pharmaceutical, Medical Device, and Healthcare Companies
The pharmaceutical and medical device industry has become one of the most actively prosecuted sectors in FCPA enforcement, generating a wave of significant resolutions over the past fifteen years. The reason is structural: in most countries outside the United States, healthcare is predominantly government-run, meaning that the doctors, hospital administrators, and purchasing officials who prescribe, purchase, or approve drugs and devices are employees of state-owned institutions—and therefore “foreign officials” under the FCPA.
Major pharmaceutical companies including Pfizer, GlaxoSmithKline, Teva, and Abbott Laboratories have all entered into FCPA resolutions involving conduct in markets ranging from China and Russia to Iraq, Saudi Arabia, and across Latin America. The typical fact pattern involves payments to physicians, hospital administrators, or health ministry officials to prescribe or approve the company’s products—conduct that, in a domestic context, would raise concerns under the Anti-Kickback Statute, but which in an international context triggers FCPA liability when the recipient is a government employee.
Medical device companies face similar exposure whenever they seek formulary approval, reimbursement coding decisions, or procurement preferences from state-run health systems. The global expansion strategies of US pharma and medical device companies, combined with distribution models that rely heavily on local partners and distributors in high-risk markets, have made this sector a top FCPA enforcement priority.
Financial Services, Banking, and Investment Firms
The financial services industry presents FCPA risks that are distinct in character from those found in sectors like energy or defense, but no less serious. Banks, investment banks, and asset managers interact with foreign government officials in several important ways: sovereign wealth funds and state pension funds are among the largest institutional investors in the world; government-controlled entities are major clients of investment banking advisory and capital markets services; and the “pay-to-play” dynamic—providing employment, consulting fees, or other benefits to officials of state-owned funds or enterprises in exchange for investment mandates or business—has been the subject of multiple high-profile enforcement actions.
JPMorgan Chase’s resolution with the DOJ and SEC involving its Sons & Daughters hiring program in China, under which the bank provided employment to relatives of Chinese government officials in exchange for investment banking business, is perhaps the most prominent example of how personnel decisions and business development practices can create FCPA exposure for financial institutions. Similar conduct was alleged against other major financial institutions operating in Asia.
Beyond hiring practices, financial institutions face FCPA risk in sovereign debt advisory and restructuring assignments, in the financing and structuring of infrastructure projects in developing markets, in prime brokerage relationships with state-owned entities, and in asset management mandates from government-controlled institutions. Correspondent banking relationships in high-risk jurisdictions and the use of local placement agents who interact with government-controlled pension funds represent additional vectors of exposure.
Technology, Telecommunications, and Software Companies
Technology and telecommunications companies have become an increasingly prominent feature of FCPA enforcement, a trend that reflects both the global expansion of the US technology sector and the significant role that government procurement plays in telecommunications infrastructure. In many countries, national telecommunications carriers are state-owned, and the process of obtaining spectrum licenses, operating permits, or interconnection agreements requires engagement with government ministries and regulatory bodies where corruption can be endemic.
Ericsson, while a Swedish company, resolved FCPA charges in 2019 and 2022 in one of the most significant anti-corruption resolutions in history, involving improper payments in numerous countries over many years. The case is instructive for US technology companies because it illustrates the breadth of conduct that can give rise to liability—from payments to government officials to secure contracts, to the use of sham consultants, to the provision of travel and entertainment to officials of state-owned telecoms.
For US software and enterprise technology companies, significant FCPA risk arises in government IT procurement processes, where winning a contract to provide software systems to a foreign ministry or state enterprise may require navigating a corrupt procurement environment. Cloud service providers, cybersecurity firms, and enterprise software vendors selling to government agencies in high-risk jurisdictions must build robust third-party due diligence into their channel partner programs and sales practices.
Construction, Engineering, and Infrastructure
Large-scale construction, engineering, and infrastructure projects—ports, airports, highways, power plants, water treatment facilities—are almost invariably financed or owned by governments, particularly in developing markets. The procurement of such projects is often conducted through processes that are opaque, poorly regulated, and susceptible to corruption. For US engineering and construction firms pursuing international infrastructure work, FCPA risk is a fundamental business reality.
The risk is compounded by the complexity of major infrastructure projects, which typically involve multiple layers of subcontractors, local partners, agents, and consultants—each of which represents a potential channel through which improper payments might flow without the knowledge of the US company at the top of the project hierarchy. The duration of major infrastructure projects—often five to ten years from contract award through completion—means that a company’s FCPA exposure can span many years and involve interactions with successive generations of government officials.
Customs clearance for construction equipment and materials, work permit processes for expatriate employees, environmental permitting, and zoning approvals are all pressure points at which local officials in corrupt environments may seek improper payments. Engineering and construction companies must train project-level personnel, not just home-office compliance teams, to recognize and report these solicitations.
Mining, Natural Resources, and Commodities Trading
Mining and natural resources companies face FCPA risk profiles that closely parallel those of the oil and gas sector. Mineral deposits are owned by the state in most countries, and the right to extract them is granted through concession agreements, licenses, and permits issued by government authorities. In the mining-intensive regions of sub-Saharan Africa, South America, and Central Asia, these processes can be vulnerable to corruption.
Commodities traders present a somewhat different but equally serious risk profile. Major commodities trading houses—including those with significant US operations or US-listed securities—have been the subject of FCPA investigations involving payments made through brokers and intermediaries to officials of state-owned commodities companies in exchange for purchase contracts. The Glencore FCPA resolution, which also implicated US conspiracy and money laundering charges, illustrates the extent to which commodities trading conduct can attract US law enforcement attention.
Manufacturing and Consumer Goods Companies with International Operations
While manufacturing and consumer goods companies may not immediately come to mind in discussions of FCPA risk, US companies in these sectors with significant international operations face meaningful exposure, particularly when they operate through local subsidiaries or joint ventures in high-risk markets. Obtaining import licenses, customs approvals, product registrations, and distribution permits often requires engagement with government agencies where demands for facilitating payments are not uncommon.
Consumer goods companies seeking to enter or expand in markets such as China, Brazil, India, or countries across Southeast Asia and Africa routinely encounter regulatory approval processes that create corruption risk. Companies in the food and beverage, consumer electronics, and automotive sectors have appeared in FCPA enforcement actions, and the common thread is typically the use of local agents or distributors who made improper payments to government officials to smooth the path for imports, licenses, or regulatory approvals without adequate oversight from the US parent company.
Cross-Cutting Risk Factors: Acquisitions, Third Parties, and Successor Liability
Two risk vectors cut across all industries and deserve particular emphasis. First, mergers and acquisitions present significant FCPA exposure when a US company acquires or merges with a foreign business that has engaged in pre-acquisition corrupt conduct. Under successor liability principles, a US acquirer can inherit the FCPA liability of a target company, making pre-acquisition FCPA due diligence an essential element of any cross-border transaction. The DOJ and SEC have provided guidance encouraging voluntary disclosure of pre-acquisition misconduct discovered through due diligence, and have generally treated good-faith compliance remediation efforts favorably. Nevertheless, the costs of resolving inherited FCPA violations—including fines, disgorgement of profits, and compliance monitorship—can dwarf the benefits of the underlying transaction.
Second, the use of third-party intermediaries remains the single most common pathway through which FCPA violations occur across all industries. Whether the intermediary is a sales agent in a defense procurement, a distributor in a pharmaceutical market, a consultant in an energy project, or a customs broker in a manufacturing operation, inadequate oversight of third-party conduct is a pervasive source of corporate FCPA liability. A robust third-party due diligence program—including risk-based vetting, contractual anti-bribery representations, training, and ongoing monitoring—is not merely good practice; it is a prerequisite for any company with meaningful international operations.
What Businesses Should Do: Building a Risk-Proportionate Compliance Program
The DOJ’s FCPA Corporate Enforcement Policy, as revised in recent years, reflects an enforcement philosophy that rewards companies that proactively build effective compliance programs, voluntarily disclose misconduct, cooperate fully with government investigations, and remediate identified deficiencies. A company with a genuinely effective compliance program—not merely one that exists on paper—is in a materially better position, both in terms of reducing the likelihood of violations and in terms of securing more favorable treatment if violations occur.
The hallmarks of an effective FCPA compliance program include, at minimum, a clear anti-bribery policy endorsed by senior leadership, a risk-based assessment of the company’s FCPA exposure calibrated to its geographic footprint, business model, and use of intermediaries, a rigorous third-party due diligence process, regular training tailored to the specific roles and risk exposures of relevant employees, financial controls designed to detect and prevent improper payments, and a confidential reporting mechanism that employees and third parties can use to raise concerns without fear of retaliation.
The adequacy of a compliance program is judged not by its existence but by its actual implementation and effectiveness in practice. The DOJ’s guidance on Evaluation of Corporate Compliance Programs provides a detailed framework for assessing whether a program is genuinely operationalized or merely aspirational—and businesses in high-risk industries should use that framework as a regular benchmark for their own programs.
For companies in any of the high-risk sectors discussed in this article, the question is not whether FCPA compliance deserves serious attention, but whether the level of attention and resources being devoted to it is proportionate to the company’s actual risk profile. The cost of a robust compliance program is a small fraction of the potential cost of an FCPA enforcement action—to say nothing of the collateral business, reputational, and relationship damage that invariably accompanies a major government investigation.
About This Article: This article has been prepared by our FCPA and Anti-Corruption Practice Group for general informational purposes. It does not constitute legal advice and should not be relied upon as such. Companies seeking guidance on FCPA compliance, risk assessment, or investigations should consult with qualified legal counsel. If you have questions about how the FCPA may affect your business, please contact our firm.
